Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2023-28413

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
Attacker Value
Unknown

CVE-2013-2183

Disclosure Date: December 10, 2019 (last updated November 27, 2024)
Monkey HTTP Daemon has local security bypass
Attacker Value
Unknown

CVE-2013-2159

Disclosure Date: December 10, 2019 (last updated November 27, 2024)
Monkey HTTP Daemon: broken user name authentication
Attacker Value
Unknown

CVE-2013-1771

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
Attacker Value
Unknown

CVE-2014-5336

Disclosure Date: August 26, 2014 (last updated October 05, 2023)
Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request that triggers an error message.
0
Attacker Value
Unknown

CVE-2013-2182

Disclosure Date: June 13, 2014 (last updated October 05, 2023)
The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrated by an encoded forward slash.
0
Attacker Value
Unknown

CVE-2013-3843

Disclosure Date: June 13, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP header.
0
Attacker Value
Unknown

CVE-2013-2163

Disclosure Date: June 13, 2014 (last updated October 05, 2023)
Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the file size in the Range HTTP header.
0
Attacker Value
Unknown

CVE-2013-3724

Disclosure Date: August 01, 2013 (last updated October 05, 2023)
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.
0
Attacker Value
Unknown

CVE-2013-2181

Disclosure Date: July 29, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Directory Listing plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows attackers to inject arbitrary web script or HTML via a file name.
0